Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.4-debian-fips, 1.8.4-debian13-fips, 1.8.4-fips

Index digest:

sha256:a0a5571dbea129c37354e4b460e576de32a32b414a1568f1295eea4d1daa2521

Manifest digest:

sha256:3274d2a7fd3b05e8167103848b1a23ff83341561166312769199f5a6e8c0815e

Size

35.74 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:8b597549e8060d0189f51d17ab3539bfa64c7ae98516c8d6b34799e862a9b27d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:ec2302946316b98948c328a48d05e498e500d8e0cb94e417dab44a1f3dc9cc27
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:1b568adad2fbad1c94858fa51a858bc79f2c507d15191bf98817cb477a228d86
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:c5f3b929e9482566e695e2e5cbfeb05b6f7c666cc0b17d9b4b363a0c258a5192
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:090f8e8670a67580c7faf9e920bd65175da87dc705ae8efd789a99e045eea5c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:02df8fb6f81aabc866c78acc1bd5971bfa898c47fc3376965a08f8b85900bcff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:7d288638f0bc3085e83c9386b9d48987ec37d63caecf8442b721061c3518da33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:1bf28ac98eb92a46303a7df44efbd3ac6364fedcffb0565f77f628ca8cd44b20
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:92e32dbe0358934236a265b16e2e4c78a00b2912d77414fcd2e66da110a51d61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:2fc6e17b5919573b86f566d3a42111ddcbc969d1ed89d882fb240ee2df1afb5f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:fdfedd8bccddb9c1b29a1cdc48d181dd5b114bda09185047cd71d2ab834c7561
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:901dfc95b7bcdb3dfeea6e1f1873316a44f600c1a27e96f28dab1ae1ebfdaa22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:bc16beb025a84e6b15ee445d50f10dfe2f4ac04b5da13c5c0d8f54dffab37639
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:4945926dea86228b4d12b5207d137c46ecb7cf7624c3275e2594e0626d5cd587
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:ae9294386cc425004eebb8174cd20800a60d2c26cb42f5ef86e15154caa15f16
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:89d8f55a4e87924e59436772df76daf3025c3bef477bad5d8a928942ceafad7e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:f993406a7e7e23ac03e94ec3ebbe7374fc727c4b323507cdc55cb846073182ae